CVE-2014-5214

NetIQ Access Manager 4.x < 4.0.1 HF3 - Authenticated XML External Entity Injection via iManager Query Parameter

Title source: llm
STIX 2.1

Description

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Scores

EPSS 0.0050
EPSS Percentile 66.2%

Details

Status published
Products (2)
microfocus/access_manager 4.0
microfocus/access_manager 4.0.1
Published Dec 23, 2014
Tracked Since Feb 18, 2026